On Tuesday 2012-04-17 04:56, Gao feng wrote: >Currently the sysctl of netfilter proto is not isolated, so when >changing proto's sysctl in container will cause the host's sysctl >be changed too. it's not expected. I wonder if it made sense to do the configuration of NFCT via netlink as well, and deprecate the sysctl interface. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html